Difference between revisions of "Boulder"

From OWASP
Jump to: navigation, search
(Always tinkering .. :/)
m
(3 intermediate revisions by 2 users not shown)
Line 10: Line 10:
 
== Upcoming Events ==
 
== Upcoming Events ==
  
====Thursday, June 27th at 6pm – Gene Kim on DevOps====
+
====Thursday, September 19th at 6pm – Bill Jackson: Secure Coding Mechanics====
  
  
 
'''About the speaker'''<br>
 
'''About the speaker'''<br>
'''Gene Kim''' is a multiple award winning CTO, researcher and author. He was founder and CTO of Tripwire, which commercialized the open source software he wrote in 1992 with Dr. Gene Spafford at Purdue University. He is the author of “[http://www.amazon.com/Visible-Ops-Handbook-Implementing-Practical/dp/0975568612/ref=sr_1_1?ie=UTF8&qid=1327709357&sr=8-1 The Visible Ops Handbook],” and “[http://www.amazon.com/Visible-Ops-Security-Operations-ebook/dp/B003J35A0A/ref=sr_1_2?ie=UTF8&qid=1327709357&sr=8-2 The Security Visible Ops Handbook],”which has sold over 200K copies to date. Gene is also the author of [http://itrevolution.com/books/phoenix-project-devops-book/ The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win].
+
'''Bill Jackson''' has been a software engineer with Raytheon for 15 years. He has worked as the secure coding lead for the GPS program (yeah, that GPS), and has helped define and implement secure coding processes and practices for several other programs. His experience extends to Java EE, Agile software development, concurrency, and user interface design. Bill has MS in computer science from the University of Colorado at Denver and a BS from Colorado State University and holds a CISSP and CompTIA Security+ certification.
 
+
Gene’s area of passion is helping companies build super-tribes where Development, IT Operations, Product and Project Management and Information Security simultaneously maximize throughput of features from “code complete” to “in production,” without causing chaos and disruption to the IT environment. He’s helped some of the largest Internet properties, such as Microsoft, Yahoo!, AOL and Microsoft companies he’s worked with Microsoft. He loves finding and fixing bottlenecks which impede and frustrate the entire organization, enabling management from each tribe to achieve the greater organizational goals.
+
  
 
{| style="width:100%;" border="0" align="left" cellpadding="5"
 
{| style="width:100%;" border="0" align="left" cellpadding="5"
 
  |-
 
  |-
 
  | style="width:6em;" | '''When'''
 
  | style="width:6em;" | '''When'''
  |                    | Thursday, June 27th
+
  |                    | Thursday, September 19th
 
  |-
 
  |-
  |                   | '''Agenda'''
+
  | style="width:6em;vertical-align:text-top;" | '''Agenda'''
  |                    | 6:00 - 6:30: Food, drink, and networking<br>6:30 - 7:00: Chapter business and group discussion<br>7:00 - 8:00: '''Gene Kim on DevOps:''' Maximizing the benefit of DevOps without sacrificing secure code development practices.
+
  |                    | 6:00 - 6:30: Food, drink, and networking<br>6:30 - 7:00: Chapter business and group discussion<br>7:00 - 8:00: '''Secure Coding Mechanics:''' Bill will bring his experience as a software engineer and secure coding lead to discuss common vulnerabilities in both development and architecture including:
 +
*Integer overflow/underflow
 +
*Filename/path validation
 +
*Excessive logging
 +
*Debug modes/maintenance hooks/configuration by convention
 +
*Insecure password handling (back-end handling)
 +
*Insecure start-up and shut-down
 
  |-
 
  |-
 
  |                    | '''Location'''
 
  |                    | '''Location'''
  |                    | [https://aerstone.com/ Aerstone], located at [https://maps.google.com/maps?q=1711+Pearl+St,+Boulder,+CO+80302&hl=en&ll=40.018955,-105.272412&spn=0.005801,0.016512&sll=40.019446,-105.273058&layer=c&cbp=13,345.63,,0,0.03&cbll=40.019323,-105.273016&hnear=1711+Pearl+St,+Boulder,+Colorado+80302&t=m&z=17&panoid=5v0RhKi7sjpi-Z5HcgKFFw 1711 Pearl St.] (3rd floor). '''Subject to change to accommodate overflow attendance.'''
+
  |                    | [https://aerstone.com/ Aerstone], located at [https://maps.google.com/maps?q=1711+Pearl+St,+Boulder,+CO+80302&hl=en&ll=40.018955,-105.272412&spn=0.005801,0.016512&sll=40.019446,-105.273058&layer=c&cbp=13,345.63,,0,0.03&cbll=40.019323,-105.273016&hnear=1711+Pearl+St,+Boulder,+Colorado+80302&t=m&z=17&panoid=5v0RhKi7sjpi-Z5HcgKFFw 1711 Pearl St.] (3rd floor).
 
  |-
 
  |-
 
  |                    | '''Parking'''
 
  |                    | '''Parking'''
 
  |                    | Free parking one block north of Aerstone through the [http://files.meetup.com/3503072/Parking.png Whittier Neighborhood Zone].
 
  |                    | Free parking one block north of Aerstone through the [http://files.meetup.com/3503072/Parking.png Whittier Neighborhood Zone].
 
  |-  
 
  |-  
|                    | '''Virtual'''
 
|                    | Remote attendees may participate through [https://questconsultants.webex.com/questconsultants/j.php?ED=207871237&UID=0&RT=MiM2 WebEx].
 
|-
 
 
  |                    | '''RSVP'''
 
  |                    | '''RSVP'''
  |                    | Available through [http://www.meetup.com/OWASP-Boulder/events/124446512/ MeetUp.com].
+
  |                    | Available through [http://www.meetup.com/OWASP-Boulder/events/135038952/ MeetUp.com].
 
  |}
 
  |}
  

Revision as of 22:24, 4 September 2013

Contents

OWASP Boulder

Welcome to the Boulder chapter homepage. The chapter leader is Mark Major.
Click here to join the local chapter mailing list.

Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is and open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter.

Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG

Special Thanks

The Boulder chapter is grateful for the continued sponsorship of Aerstone. Thank you for providing the venue, refreshments, and other resources necessary to keep the chapter running strong.

BoulderSponsorAerstone.png


Upcoming Events

Thursday, September 19th at 6pm – Bill Jackson: Secure Coding Mechanics

About the speaker
Bill Jackson has been a software engineer with Raytheon for 15 years. He has worked as the secure coding lead for the GPS program (yeah, that GPS), and has helped define and implement secure coding processes and practices for several other programs. His experience extends to Java EE, Agile software development, concurrency, and user interface design. Bill has MS in computer science from the University of Colorado at Denver and a BS from Colorado State University and holds a CISSP and CompTIA Security+ certification.

When Thursday, September 19th
Agenda 6:00 - 6:30: Food, drink, and networking
6:30 - 7:00: Chapter business and group discussion
7:00 - 8:00: Secure Coding Mechanics: Bill will bring his experience as a software engineer and secure coding lead to discuss common vulnerabilities in both development and architecture including:
  • Integer overflow/underflow
  • Filename/path validation
  • Excessive logging
  • Debug modes/maintenance hooks/configuration by convention
  • Insecure password handling (back-end handling)
  • Insecure start-up and shut-down
Location Aerstone, located at 1711 Pearl St. (3rd floor).
Parking Free parking one block north of Aerstone through the Whittier Neighborhood Zone.
RSVP Available through MeetUp.com.